CVE-2025-54791

OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openmicroscopy:omero-web:*:*:*:*:*:*:*:*

History

23 Sep 2025, 18:13

Type Values Removed Values Added
Summary
  • (es) OMERO.web ofrece una infraestructura de cliente y complementos web. Antes de la versión 5.29.2, si se producía un error al restablecer la contraseña de un usuario con la opción "Olvidé mi contraseña" en OMERO.web, el mensaje de error que se mostraba en la página web podía revelar información sobre el usuario. Este problema se ha corregido en la versión 5.29.2. Una solución alternativa consiste en deshabilitar la opción "Olvidé mi contraseña" en OMERO.web mediante la propiedad de configuración omero.web.show_forgot_password.
References () https://github.com/ome/omero-web/commit/8aa2789e8f759c73f1517abe9a0abd44e86644ad - () https://github.com/ome/omero-web/commit/8aa2789e8f759c73f1517abe9a0abd44e86644ad - Patch
References () https://github.com/ome/omero-web/security/advisories/GHSA-gpmg-4x4g-mr5r - () https://github.com/ome/omero-web/security/advisories/GHSA-gpmg-4x4g-mr5r - Vendor Advisory
First Time Openmicroscopy omero-web
Openmicroscopy
CPE cpe:2.3:a:openmicroscopy:omero-web:*:*:*:*:*:*:*:*

13 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 14:15

Updated : 2025-09-23 18:13


NVD link : CVE-2025-54791

Mitre link : CVE-2025-54791

CVE.ORG link : CVE-2025-54791


JSON object : View

Products Affected

openmicroscopy

  • omero-web
CWE
CWE-209

Generation of Error Message Containing Sensitive Information